SourTrade is a persistent large-scale malvertising operation active since late 2024. It targets retail traders and cryptocurrency investors by impersonating financial and cryptocurrency brands, including TradingView, Solana, and Luno, through malicious advertisements and counterfeit landing pages. The operation primarily targets Asia-Pacific and Latin American audiences and operates campaigns in 25 languages. SourTrade uses cloaking to distinguish intended victims from researchers and automated analysis systems, serving blank or benign pages to suspected analysts. Its delivery chain avoids directly transferring a completed malware file. Instead, a landing page provides browser-executed build instructions, retrieves a legitimate runtime component, generates additional data locally, and assembles a Windows executable in memory. The resulting executable embeds malicious JavaScriptCore bytecode that is run by the Bun interpreter, then is delivered through a same-origin browser download flow. Session-specific assembly parameters produce varying executable hashes, impeding static file-based detection and forensic review of network downloads. SourTrade activity has evidence of overlap with JSCeal malvertising campaigns and the associated WEEVILPROXY/MeadowLocust cluster, but SourTrade is principally tracked as a distinct malvertising operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
25 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malvertising operation active since late 2024 that impersonates trusted trading and cryptocurrency brands. Its landing pages provide browser-side assembly instructions, retrieve legitimate files from separate infrastructure, and cause the victim browser to construct malware in memory rather than downloading a finished payload.
Malvertising operation delivering browser-assembled malware via fake trading and crypto platform ads, designed to evade analysis and file-based detection by having the victim browser assemble the final payload in memory from clean components.
Large-scale malvertising operation active since late 2024/2025 that impersonates TradingView, Solana, and Luno to target retail traders and crypto investors. It uses cloaking on landing pages and a browser-side assembly pipeline to fetch a clean Bun runtime, combine it with delivered blobs and locally generated AES-CTR bytes, and assemble the final malware executable in memory before delivering it via a ServiceWorker-controlled same-origin download path.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.